EMZETT.
Login

User Input

In short: Data that a program interactively accepts from the user during runtime — e.g. via the console, a form field, or a dialog window.

In more detail: Input comes in as text and often first has to be converted into the right data type (see Type Casting) before it can be further processed — for example, an entered number that’s initially available as a string. Robust programs validate user input before using it, so as not to react to unexpected or faulty input with a crash (see Exceptions).

In Depth

The golden rule of software development is: “User input is fundamentally untrustworthy.” No matter what a program asks for — a human can enter something completely different from what’s expected, whether deliberately or by accident. A simple example:

input_value = input("Enter your age: ")
age = int(input_value)  # crashes if input_value is e.g. "twelve" or empty!

More robust is a combination of validation and error handling:

input_value = input("Enter your age: ")
try:
    age = int(input_value)
    if age < 0 or age > 150:
        print("That's not a plausible age.")
    else:
        process(age)
except ValueError:
    print("Please enter a number.")

This caution isn’t an exaggeration — a large share of all security vulnerabilities in software arise because input is reused unchecked (a classic example: SQL injection, where an input is inserted directly into a database query, see SQLi). This is why a distinction is made between syntax validation (is the input even in the expected form, e.g. a valid number or email address) and semantic validation (is the value plausible in content, e.g. an age between 0 and 150).

Depending on context, HOW input arrives differs: via the command line/console (the simplest case, usually plain text), via graphical form fields (often already with client-side pre-validation, which must never replace server-side validation, though), or via files/APIs (structured formats like JSON, which do carry type information but can still be wrong or malicious in content). The basic rule — never trust blindly, always validate before processing — applies equally in all cases.

See also: Type Casting, Exceptions